mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 10:58:17 -05:00
[PR #21211] [CLOSED] fix: middleware auth header crash #64826
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/21211
Author: @ThanosTsiamis
Created: 2/6/2026
Status: ❌ Closed
Base:
dev← Head:fix/middleware-auth-header-crash📝 Commits (10+)
fe6783cMerge pull request #19030 from open-webui/devfc05e0aMerge pull request #19405 from open-webui/deve3faec6Merge pull request #19416 from open-webui/dev9899293Merge pull request #19448 from open-webui/dev140605eMerge pull request #19462 from open-webui/dev6f1486fMerge pull request #19466 from open-webui/devd95f533Merge pull request #19729 from open-webui/deva7271530.6.43 (#20093)6adde20Merge pull request #20394 from open-webui/devf9b0534Merge pull request #20522 from open-webui/dev📊 Changes
1 file changed (+12 additions, -3 deletions)
View changed files
📝
backend/open_webui/main.py(+12 -3)📄 Description
Pull Request Checklist
Fixes #20938
Before submitting, make sure you've checked the following:
devbranch. Not targeting thedevbranch will lead to immediate closure of the PR.Changelog Entry
Description
Improved the stability of the middleware by adding robust error handling for malformed Authorization headers. Previously, an incorrectly formatted header could cause the application to raise an unhandled exception. The system now validates the header structure and gracefully returns a 401 Unauthorized response if the format is invalid.
Added
Changed - Fixed - Security
Modified: backend/open_webui/main.py
Lines 1315-1325: Replaced direct string splitting with conditional validation and error handling.
Deprecated
Removed
Breaking Changes
Additional Information
Fixes #20938
Contributor License Agreement
By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.